North Korean hackers laundered stolen Bitget funds through CoW Protocol and Chainflip to convert to Bitcoin, exploiting backend vulnerabilities and third-party service compromise.
Security & Exploits ·
Security research by SlowMist identified North Korean-linked attackers moving funds stolen from Bitget through CoW Protocol and Chainflip to convert assets into Bitcoin, with the proceeds further obscured via CoinJoin. The theft originated from a zero-day vulnerability in a third-party service compromised on August 31, followed by unauthorized access to a second product's management system on September 25 using an employee credential, enabling attackers to deploy a custom withdrawal tool that executed the theft between 01:49 and 05:23 UTC on September 25 across multiple blockchains. Bitget attributed the incident to backend vulnerabilities in its wallet infrastructure rather than a compromised private key, while Chainflip rejected at least one deposit attempt linked to the laundering scheme but refunded the funds instead of freezing them. The exchange stated its User Protection Fund would compensate affected users.